Back to skill

Security audit

Alibabacloud Cms Manage

Security checks across malware telemetry and agentic risk

Overview

This is a coherent Alibaba Cloud monitoring management skill, but it needs Review because it combines broad cloud mutation authority with a few under-scoped safety and consent instructions.

Install only if you intend to let the agent manage Alibaba Cloud CMS resources with your configured aliyun credentials. Use least-privilege RAM policies, avoid granting cross-account proxy or tag mutation unless required, confirm every write command carefully, and be aware that the skill may present important prompts in Simplified Chinese.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
The skill declares a cross-account proxy API, which materially expands its authority beyond ordinary CMS management into acting on behalf of member accounts. In an agent setting, this increases blast radius and can enable unintended access, modification, or data retrieval across account boundaries if invoked without very strict scoping and authorization checks.

Context-Inappropriate Capability

Medium
Confidence
81% confidence
Finding
Including generic Tag service APIs broadens the skill from CMS-specific monitoring operations into cross-service resource metadata modification and enumeration. That scope expansion can let the agent alter tags or discover tagged resources unrelated to CMS, which may affect governance, automation, billing attribution, or reveal inventory beyond user expectations.

Context-Inappropriate Capability

Low
Confidence
72% confidence
Finding
Resource group enumeration via Resource Manager is outside the narrow CMS command scope and introduces additional organizational discovery capability. While lower risk than mutation APIs, it can still expose account structure and facilitate broader reconnaissance than users may expect from a CMS-focused skill.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill's trigger scope is very broad, covering many loosely related keywords and entire CMS module areas. That increases the chance of unintended invocation, causing the agent to enter a high-privilege cloud-management workflow when the user's request may only be informational or ambiguous, which can lead to unnecessary command execution, credential use, or exposure to operationally sensitive actions.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
Forcing all user-facing output into Simplified Chinese without user opt-in can create a safety and usability failure mode: users may misunderstand confirmations, risk disclosures, or write-operation summaries. In a cloud-management skill that already authorizes impactful CLI actions, reduced comprehension can undermine informed consent and increase the chance of accidental destructive operations.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The skill hard-codes a Chinese-only user prompt for onboarding type without any locale negotiation or user preference check. This is not a direct security exploit, but it can mislead or coerce users into accepting actions they do not fully understand, which is relevant in a workflow that can modify clusters and deployments.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
This rule mandates a specific Chinese phrase for user-facing interaction and forbids alternative wording, with no user opt-in or localization fallback. In a skill that can perform infrastructure changes, reducing clarity or user comprehension weakens informed consent and increases operational risk.

Ssd 4

Medium
Confidence
97% confidence
Finding
The guidance explicitly instructs bypassing an API/type enforcement failure by degrading unsupported APM or UMODEL rule creation into PROMETHEUS and translating expressions. That crosses an intended validation boundary and can silently create semantically different alerts, causing false negatives, false positives, or monitoring coverage gaps while presenting the operation as successful.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.